2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34750HIGH7.5An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thou...
CVE-2022-30997HIGH7.2Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which ma...
CVE-2022-30707HIGH8.8Violation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CE...
CVE-2022-29519HIGH7.5Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 ...
CVE-2022-23896MEDIUM5.4Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).
CVE-2022-0624HIGH7.3Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
CVE-2022-34134HIGH8.8Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Use...
CVE-2022-34133MEDIUM6.1Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at applicatio...
CVE-2022-34132CRITICAL9.8Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leav...
CVE-2022-31104MEDIUM5.6Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal fo...
CVE-2022-33009MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts ...
CVE-2022-32995CRITICAL9.8Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function...
CVE-2022-32994CRITICAL9.8Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachment...
CVE-2022-31103HIGH7.5lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer belo...
CVE-2022-31101HIGH8.8prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected v...
CVE-2022-31099MEDIUM6.5rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, the stack may overflow,...
CVE-2022-33879LOW3.3The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insuffi...
CVE-2022-33007HIGH8.8TRENDnet Wi-Fi routers TEW751DR v1.03 and TEW-752DRU v1.03 were discovered to contain a stack overflow via the function ...
CVE-2022-32092CRITICAL9.8D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __aja...
CVE-2022-31100MEDIUM6.5rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, rulex may crash, possib...
CVE-2022-31098HIGH7.5Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K...
CVE-2022-31096MEDIUM5.7Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an...
CVE-2022-31093HIGH7.5NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker...
CVE-2022-31092HIGH8.1Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make query...
CVE-2022-31091HIGH7.7Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In af...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now